← Back to Insights

AI Governance

Can My Firm Use Claude or ChatGPT on Client Files?

Michael K. Onyekwere··6 min read

Firms put the question to us in different words. Whether the Claude Team contract covers them. Whether uploading client files to ChatGPT is a breach. Whether they need to buy a server and run a model in the office. Underneath, it is the same question: client files hold confidential and often sensitive personal data, the AI tools can now read them, and somebody has to decide whether that is defensible.

The answer is that these tools can be used on client files lawfully. Whether your firm's use of them is lawful today turns on three things: the tier of account the firm is on, a small number of settings, and the documents the law expects to exist before processing of this kind begins.

The account tier is the first fork

The consumer and business versions of these products are different animals in data-protection terms, and most of the fear about AI and client data comes from conflating them.

Consumer accounts, the free and personal-plan versions of ChatGPT and Claude, can use what you type to train the vendor's models, subject to opt-outs the user has to notice and set. There is no contract with your firm, and the firm has no visibility of what staff put in.

The business tiers are built the other way. Claude Team and Enterprise, ChatGPT Team and Enterprise, and both vendors' API platforms do not train on your content by default, and both vendors offer processor terms, a Data Processing Addendum, the contract UK GDPR expects between a firm and its processor. We have reviewed the terms in detail, and on paper the leading vendors' business terms are strong. The specifics for OpenAI's API are set out in our setup guide.

Which makes the most dangerous configuration in common use a mundane one: a member of staff using a personal account for client work, with no contract, consumer defaults, and no oversight. If your firm does nothing else after reading this, it should establish which accounts its people actually use.

Reading client files can be lawful processing

When a tool on a business tier reads a client file, the vendor is processing that data as your processor, under contract, on your instructions. That is a recognised legal arrangement, and it is the same shape as your cloud storage or your practice-management system. The law does not require you to fence the tools off from client data.

The firm's side of that arrangement is being able to show its basis. Each purpose the AI serves needs a lawful basis, and where the files hold health information, capacity material or other special-category data, a further condition under Article 9. Those attach to the advice you are engaged to give, and the analysis has to be done and written down.

Free download

Get the Eight Documents sheet

The eight documents UK law expects a firm to hold before AI touches client data, each with what it is, where it bites, and its statutory anchor. Two pages, written for firm principals.

For partners, directors and compliance owners at firms already using AI on client files.

  • ·All eight named, from the impact assessment to the engagement-letter wording
  • ·The trap under each one, and its statutory anchor
  • ·A held-and-current checkbox against each, so you can audit the firm in minutes
  • ·The enforcement backdrop, including where directors carry personal liability

Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.

The settings can undo the contract

A sound contract is only half the position, because the products carry settings that can move data outside it. Feedback and rating features can send an entire conversation to the vendor; on one leading product it can then be stored for up to five years and used for training. Retention differs by tier too: on at least one leading business plan, saved conversations have no automatic expiry, and configurable retention arrives only at enterprise level. Sharing and connector features widen who can see what.

All of these are visible settings, and closing them is quick work. The defaults are set for the vendor's convenience, though, and the contract's protections only describe reality if the configuration matches them. Whether it does is a checkable fact about your workspace, and it should be checked and recorded.

The documents the law expects to exist first

This is where firms most often stand exposed, and it has little to do with the tools themselves.

Because AI on client files applies a new technology to sensitive personal data, the law expects a data protection impact assessment to exist before the processing begins. It expects the lawful-basis analysis inside it. Depending on the condition the assessment settles on, it can require a short statutory policy document. It expects the privacy notice to describe the AI processing, the processing register to record it, the US transfer to carry the firm's own risk assessment where the contract relies on standard contractual clauses, and the staff rules to be written. Good practice adds a signature to the staff instruction and puts what the client is told into the engagement letter.

Firms that adopted the tools first, which in our experience is the usual order of events, are running processing the paperwork has not caught up with. The practical response is to complete the documents now, at priority, and to close the obvious exposures immediately; whether the tools can stay in use as they are is what the assessment confirms.

If your firm is FCA-regulated

There is no FCA rule against these tools because they are AI. The FCA has said it will supervise AI through its existing framework, and it has not made a separate AI rulebook. The ordinary expectations on records, supervision, outsourcing and customer outcomes carry across to how the tools are used. Whether your particular permissions and arrangements meet them is a judgement for whoever owns compliance in your firm, made on documented facts.

Do we need a local model instead?

Usually not. Everything above is settings and documentation, and it costs a fraction of buying, securing and maintaining your own model server, which also tends to mean running a less capable model than the ones your team already uses. The cases where a local model earns its keep are narrow: a client or regulator demanding that data never leaves the UK, or a vendor materially changing the terms the cloud position rests on.

Where that leaves the question

The honest answer to "can my firm use Claude or ChatGPT on client files" is that the law does not stand in the way, and the vendors' business terms hold up. The exposure, where it exists, is in the gap between what the firm is doing and what its configuration and documents say. That gap is specific, it is checkable, and it is closeable.

Free download

Get the Eight Documents sheet

The eight documents UK law expects a firm to hold before AI touches client data, each with what it is, where it bites, and its statutory anchor. Two pages, written for firm principals.

For partners, directors and compliance owners at firms already using AI on client files.

  • ·All eight named, from the impact assessment to the engagement-letter wording
  • ·The trap under each one, and its statutory anchor
  • ·A held-and-current checkbox against each, so you can audit the firm in minutes
  • ·The enforcement backdrop, including where directors carry personal liability

Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.

Frequently Asked Questions

Is it a data-protection breach to put client files into Claude or ChatGPT?

Not in itself. On a business tier with processor terms in place, the vendor processes the files as your processor, which is the same legal arrangement as cloud storage or a practice-management system. The breach risk comes from the configuration around it: consumer accounts that train on content by default, feedback features that send conversations back to the vendor, and processing that started before the firm documented its basis for it.

Do we need our clients' consent to use AI on their files?

Generally no. The firm needs a lawful basis for each purpose and, where files hold health or similar special-category data, a further condition under Article 9 UK GDPR. Those attach to the work you are engaged to do, and consent is rarely the right route for it. Clients should be told about AI processing through the privacy notice and engagement terms, which is a transparency duty rather than a consent requirement.

Do we need a DPIA before using AI on client files?

Where a firm applies a new technology to files containing sensitive personal data, the processing is squarely within the ICO's criteria for a mandatory data protection impact assessment, and the law expects the assessment before the processing begins. A firm that adopted the tools first should complete it now, and will not usually need to stop using the tools while it does, unless the assessment turns up a risk the firm cannot reduce.

Can staff use their personal ChatGPT or Claude accounts for client work?

This is the highest-risk configuration in common use. A personal account has no contract with the firm, may train on what staff type by default, and gives the firm no visibility or control. Client material belongs in the firm's own workspace on a business tier, and the rule belongs in a written instruction each member of staff signs.

Start with a £500 scoping review

If you need GDPR documentation, AI Act work, or a compliant AI build, the first step is a written scoping review. You get a real report, not a generic discovery call.

Claude client dataChatGPT client files GDPRlaw firm AI complianceprofessional firms AIClaude Team GDPRAI client confidentiality UK